| File name: | SETUP.exe |
| Full analysis: | https://app.any.run/tasks/3f73da96-29a6-435b-b563-a3c1d77e4e43 |
| Verdict: | Malicious activity |
| Analysis date: | February 03, 2024, 15:33:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive |
| MD5: | EC6A6A7431C9A8E9BB88C03027B358D1 |
| SHA1: | 3D6598DA95AE6AE732A68CF0F3A7E0F1ABECEC0E |
| SHA256: | A93F018F6157CA6636B7B0F783A9D42F404D2F66BD9FE455712CF07AD7E2272A |
| SSDEEP: | 98304:oNOG/IdR86YzIuQsJ22ki7XrZNlJ+uLrh4EksRU9TUAgGATg8mM6CGyCajLHEdSL:aFBd+n+d |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2000:06:16 20:00:04+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 69632 |
| InitializedDataSize: | 98304 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x84a7 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.11.15.0 |
| ProductVersionNumber: | 2.11.15.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | Tiny_0213 |
| CompanyName: | General |
| FileDescription: | TNC0402.2003.04.02 |
| FileVersion: | 1.00.000 |
| InternalName: | stub32i.exe |
| LegalCopyright: | - |
| OriginalFileName: | stub32i.exe |
| ProductName: | MyDSC |
| ProductVersion: | 1.00.000 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\Users\admin\AppData\Local\Temp\SETUP.exe" | C:\Users\admin\AppData\Local\Temp\SETUP.exe | — | explorer.exe | |||||||||||
User: admin Company: General Integrity Level: MEDIUM Description: TNC0402.2003.04.02 Exit code: 3221226540 Version: 1.00.000 Modules
| |||||||||||||||
| 1072 | "C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe" -RegServer | C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe | — | Setup.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield (R) Setup Engine Exit code: 0 Version: 6, 31, 100, 1190 Modules
| |||||||||||||||
| 2088 | "C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\Setup.exe" | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\Setup.exe | SETUP.exe | ||||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield (R) Setup Launcher Exit code: 0 Version: 6, 20, 100, 1362 Modules
| |||||||||||||||
| 2628 | "C:\Users\admin\AppData\Local\Temp\SETUP.exe" | C:\Users\admin\AppData\Local\Temp\SETUP.exe | explorer.exe | ||||||||||||
User: admin Company: General Integrity Level: HIGH Description: TNC0402.2003.04.02 Exit code: 0 Version: 1.00.000 Modules
| |||||||||||||||
| 3096 | "C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" /REGSERVER | C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe | — | IKernel.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield (R) Setup Engine Exit code: 0 Version: 6, 31, 100, 1190 Modules
| |||||||||||||||
| 3248 | C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\IKernel.exe -Embedding | C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe | svchost.exe | ||||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield (R) Setup Engine Exit code: 0 Version: 6, 31, 100, 1190 Modules
| |||||||||||||||
| (PID) Process: | (3248) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\corecomp.ini |
Value: 1 | |||
| (PID) Process: | (3248) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\ctor.dll |
Value: 1 | |||
| (PID) Process: | (3248) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\objectps.dll |
Value: 1 | |||
| (PID) Process: | (3248) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\iuser.dll |
Value: 1 | |||
| (PID) Process: | (3248) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\InstallShield\IScript\iscript.dll |
Value: 1 | |||
| (PID) Process: | (3248) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\Setup.inx | binary | |
MD5:EBCF82227081D751F473E7C27445A9CF | SHA256:901CD123808483A2B22E2328CEE3BE7CF065482ED5C4B6C9745E4EFE6578CE6F | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\pftw1.pkg | compressed | |
MD5:90365C4341FDA04FF6FA92AB506B7B0E | SHA256:2DA0E80B7C839A84E56C1A43CDA7434DD5F13F5D1C0FB0C78C29DE6852747795 | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\Setup.exe | executable | |
MD5:02A229BA8498F49336B37AE4B3A775F1 | SHA256:278D71D67E7EDFAF2F6773C51A6D9DB9627278C47D0BED4709762FB9F0DC7351 | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\plf351E.tmp | text | |
MD5:19A2283172165182D05BBD5745372F62 | SHA256:379ADDFC2E4A0309EC0526507D564FC79EEB6635963C0E84F10CB8B103036C54 | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\data1.hdr | binary | |
MD5:A95C06F6C593D4F8A1DBA0DF84A00FB8 | SHA256:1BA70BF2F92D6FB2EE63AA9FFD571708A48F1660A1F30F91913D24511D85A817 | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\data1.cab | compressed | |
MD5:0AF6574032E96B724AFDC8527C1D84C3 | SHA256:43B5B41ABF20B989C41F2CDB44F4DE130D2ED867ABA40F469CC85EA17E71CF49 | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\Setup.ini | text | |
MD5:A848571EF69C8820FEC66E4AFAC27DDC | SHA256:FDC054E2653560EA9FE7941CDE407A52398DCDC5AC0B37EA131C4406A52E0C7B | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\data2.cab | compressed | |
MD5:C37915BE02D0F7D78489FFD0FDD83B2D | SHA256:812CBE3F843D701E8010640BEF588E18031DC67D253E2D6D58225B7658797955 | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\pft353F~tmp\Disk1\layout.bin | binary | |
MD5:928AECBA357045D61DA3E57976ABFD97 | SHA256:794636658F16E377F6272ED7995DAF5710725683BFA7DDD5E0654B3E2FD8FCDF | |||
| 2628 | SETUP.exe | C:\Users\admin\AppData\Local\Temp\ext351F.tmp | text | |
MD5:19A2283172165182D05BBD5745372F62 | SHA256:379ADDFC2E4A0309EC0526507D564FC79EEB6635963C0E84F10CB8B103036C54 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |